CVE-2019-12471
—CVSS 3.0
6.1 medium
EPSS
1%p68
Published
()
Modified
Description
Wikimedia MediaWiki 1.30.0 through 1.32.1 has XSS. Loading user JavaScript from a non-existent account allows anyone to create the account, and perform XSS on users loading that script. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.
In the news0 stories
No ingested article mentions this CVE yet.